Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 379
CVE-2016-9901
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
CVE-2016-9901
HTML tags received from the Pocket server will be processed without sa ...
CVE-2016-9900
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9900
External resources that should be blocked when loaded by SVG images ca ...
CVE-2016-9899
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9899
Use-after-free while manipulating DOM events and removing audio elemen ...
CVE-2016-9898
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9898
Use-after-free resulting in potentially exploitable crash when manipul ...
CVE-2016-9897
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9897
Memory corruption resulting in a potentially exploitable crash during ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-9901 HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2016-9901 HTML tags received from the Pocket server will be processed without sa ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2016-9900 External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. | CVSS3: 7.5 | 10% Низкий | около 8 лет назад | |
CVE-2016-9900 External resources that should be blocked when loaded by SVG images ca ... | CVSS3: 7.5 | 10% Низкий | около 8 лет назад | |
CVE-2016-9899 Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. | CVSS3: 9.8 | 21% Средний | около 8 лет назад | |
CVE-2016-9899 Use-after-free while manipulating DOM events and removing audio elemen ... | CVSS3: 9.8 | 21% Средний | около 8 лет назад | |
CVE-2016-9898 Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2016-9898 Use-after-free resulting in potentially exploitable crash when manipul ... | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2016-9897 Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2016-9897 Memory corruption resulting in a potentially exploitable crash during ... | CVSS3: 7.5 | 3% Низкий | около 8 лет назад |
Уязвимостей на страницу